Install the add-on, create the Meta app, configure credentials and webhooks, link a tested Maxbot flow, move to a production number and permanent token, and build approved carousel templates.
Separate add-onMeta Cloud APIWebhook deliveryProduction tokenCarousel templates
01
Product boundary
Maxbot WhatsApp Integration is an add-on. It extends an installed and authorized Maxbot Core plugin; it does not replace the core builder.
Core owns agents, topics, entities, conversation blocks, Flow Editor logic, Users Data, training, and the project model. The add-on receives Meta webhook events, resolves the linked WhatsApp project and assigned flow, passes the message into Maxbot, and sends the resulting response through WhatsApp Cloud API.
Build in Core
Create and test the complete conversation,including keywords, fallbacks, validation, joins, and endings,before connecting the channel.
Connect in the Add-on
Configure Meta assets, webhook delivery, the linked project, production credentials, templates, testing, and channel-specific operations.
02
Prerequisites
An installed, active, and authorized Maxbot Core plugin.
A complete Maxbot topic/flow that already passes Test Flow.
The installable Maxbot WhatsApp Integration add-on ZIP.
A Meta developer account and a Business Portfolio.
A Meta app using the WhatsApp Business use case.
A public HTTPS WordPress site that Meta can reach.
Administrator access to WordPress and appropriate control of the Meta business assets.
Do not begin with production credentials. Validate the connection with Meta’s development assets first, then move deliberately to the real number and permanent token.
03
Install the WhatsApp add-on
Confirm Maxbot Core is installed, active, authorized, and functioning.
Open Plugins → Add New Plugin → Upload Plugin.
Choose the installable WhatsApp add-on ZIP and select Install Now.
Activate the add-on.
Open Maxbot → WhatsApp Integration and confirm Settings, Templates, Dashboard/Logs, and Troubleshooting are available.
Dependency: do not deactivate or remove Maxbot Core while the add-on is active.
04
Setup map
Create the Meta app and select the WhatsApp Business use case.
Validate Meta’s test phone assets.
Copy development credentials into Maxbot.
Configure the callback URL, verify token, and messages subscription.
Create and link a WhatsApp project to a tested Maxbot flow.
Add the real business number and permanent system-user token.
Run a two-way production test and inspect logs.
Complete business verification and template approval when required.
05
Create the Meta app
Open Meta for Developers and select My Apps → Create App.
Enter an app name and contact email.
Choose the WhatsApp Business use case.
Select the Business Portfolio that should own the WhatsApp Business Account.
Review the selection, create the app, and complete any confirmation Meta requests.
On the app dashboard, add or customize the WhatsApp product and open its API Setup.
Create a dedicated Meta app owned by the correct Business Portfolio. Click to enlarge.Select WhatsApp Business so the app receives the required Cloud API configuration. Click to enlarge.
06
Validate Meta development phone assets
Open the WhatsApp product’s API Setup or Try it out area.
Select Meta’s test sender number.
Add a recipient number that you control and verify it when Meta requires confirmation.
Send Meta’s sample message.
Confirm it arrives before adding Maxbot to the path.
Record the App ID, WABA ID, test Phone Number ID, and temporary access token shown for the development assets.
Isolation test: if Meta’s own sample does not arrive, fix the Meta asset or recipient setup before troubleshooting Maxbot.
Use Meta’s development sender and test recipient before configuring the Maxbot webhook. Click to enlarge.Choose a recipient you can access so both outgoing delivery and incoming replies can be checked. Click to enlarge.
07
Credential reference
Value
Source
Purpose
App ID
Meta app dashboard
Identifies the Meta app.
App Secret
Meta app basic settings
Validates webhook signatures. Keep it private.
WABA ID
WhatsApp API Setup
Identifies the WhatsApp Business Account.
Phone Number ID
WhatsApp API Setup
Identifies the sender in Cloud API calls.
Access token
Temporary token for development; system-user token for production
Authorizes API requests.
Verify token
Created by you in Maxbot
Must exactly match Meta’s webhook configuration.
Callback URL
Generated by Maxbot
Public HTTPS endpoint that receives Meta webhook events.
Identifiers must belong together. A WABA ID, Phone Number ID, app, token, and production phone drawn from different business assets can pass some checks while failing message delivery.
08
Enter development credentials in Maxbot
Open Maxbot → WhatsApp Integration → Settings.
Copy the App ID from the Meta app dashboard.
Reveal and copy the App Secret from Meta’s basic app settings.
Copy the WABA ID, development Phone Number ID, and temporary access token from WhatsApp API Setup.
Paste each value into the matching Maxbot field without surrounding spaces or labels.
Create a strong verify token that is not the App Secret or access token.
Save the settings before configuring the webhook in Meta.
Temporary tokens expire. They are appropriate only for the development phase and must be replaced before production.
09
Configure the webhook
In Maxbot WhatsApp settings, confirm the verify token and credentials are saved.
Copy the callback URL generated by Maxbot.
In Meta, open WhatsApp → Configuration and choose to configure the webhook.
Paste the callback URL into Meta’s Callback URL field.
Paste the exact same verify token.
Select Verify and Save.
In the webhook fields list, subscribe to messages.
Copy the HTTPS callback URL generated by Maxbot and keep its verify token saved. Click to enlarge.Meta accepts the callback only when it can reach the site and both verify-token values match exactly. Click to enlarge.
10
Verify webhook delivery and app subscription
Open WhatsApp Integration → Troubleshooting.
Select Test Connection.
If webhook delivery is disabled, enable it, save, and retest.
Confirm the app, WABA, phone assets, callback, and subscription are detected.
Confirm the WABA is subscribed to the app and the messages field is active.
Send a Meta test message and reply from the recipient phone.
Verify the incoming event appears in Maxbot’s logs.
Run the built-in test after saving credentials and subscribing Meta’s webhook. Click to enlarge.A successful test confirms the main Meta and Maxbot integration checks. Click to enlarge.
11
Create a WhatsApp project
In Maxbot Core, create and fully test the topic/flow that should answer WhatsApp messages.
Open Projects and select Add New Project.
Enter a project name and select the WhatsApp project/channel type.
Assign the correct agent and conversation flow.
Choose whether any incoming message or only specific messages can start the flow.
For a specific-message trigger, enter keywords or phrases and choose Exact, Contains, or Starts with.
Enable “only trigger if no active conversation exists” when a new trigger should not restart an ongoing session.
Optionally configure a website WhatsApp launcher and prefilled message.
Save and enable the project.
12
Link the project and flow
Open WhatsApp Integration settings.
Locate Linked WhatsApp Project.
Select the WhatsApp project created for this integration.
Save the settings.
Return to Troubleshooting and run the connection test again.
Confirm the result identifies the linked project and assigned flow.
A connected Meta app is not enough. Incoming messages cannot start the intended conversation until the integration resolves an enabled WhatsApp project with an assigned flow.
Select the enabled WhatsApp project whose assigned flow should handle incoming messages. Click to enlarge.
13
Add the production phone number
In WhatsApp API Setup, select Add phone number.
Enter the public display name, business category, and business description.
Enter the real phone number.
Complete Meta’s verification method for that number.
Select the new number in API Setup.
Copy its Phone Number ID and confirm the WABA ID belongs to the same business account.
Add and verify the production phone number under the same business assets used by the app. Click to enlarge.
14
Create a permanent system-user token
Open Meta Business Settings.
Create or select a system user controlled by the business.
Assign the Meta app and WhatsApp Business Account assets.
Grant only the WhatsApp permissions required to manage and send messages.
Generate a system-user token for the app.
Copy the token immediately and store it in the business’s approved secret manager.
Permanent does not mean public. Never place the token in screenshots, support tickets, chat messages, frontend JavaScript, or source control. Rotate it after suspected exposure or ownership changes.
15
Replace test credentials with production values
Open Maxbot WhatsApp settings.
Replace the temporary token with the system-user token.
Replace the test Phone Number ID with the production Phone Number ID.
Confirm the App ID, App Secret, and WABA ID match the production number’s assets.
Enter the public business number in international format.
Save the settings.
Run Test Connection and confirm the detected number, WABA subscription, webhook, linked project, and assigned flow.
Retest after replacing development assets so the result identifies the real business number. Click to enlarge.
16
Run an end-to-end production test
Open WhatsApp Integration Troubleshooting and confirm every connection check passes.
Enter a recipient number using digits in international format.
Select an approved template and send the test message.
Confirm the message arrives on the recipient phone.
Reply with text that matches the configured project trigger.
Confirm the linked project starts its assigned Maxbot flow.
Complete quick replies, keyword routes, validation, media, joins, and the final action that the flow uses.
Verify webhook-received, sent, delivered, and read events in Dashboard or Message Logs where available.
Repeat from a second WhatsApp account and after any credential, webhook, template, project, or flow change.
Send a controlled test message, reply from WhatsApp, and verify the complete two-way path. Click to enlarge.
17
Meta business verification
Meta may require Business Verification before production access or higher messaging limits are available.
Open Meta Business Settings or Security Center and start verification.
Enter the legal business name, address, phone, website, business type, and category exactly as official records show them.
Add a trading name only when the business genuinely uses it.
Choose an available verification method.
Upload a current, readable file of the exact document type Meta requests.
Review and submit the information.
Monitor the verification status and account email for follow-up requests.
After approval, confirm the app, WABA, production number, display name, and system-user assets still match.
18
WhatsApp template basics
WhatsApp message templates are created for defined business-initiated messages and reviewed by Meta. A template has a unique name, language, content, components, samples, and a status.
Use clear content that matches the real business purpose.
Provide realistic samples for variables and media.
Use only publicly accessible HTTPS sample media.
Do not place a Pending or Rejected template in a production flow.
Keep the live payload compatible with the approved structure.
19
Quick Reply and Link Carousels
Quick Reply Carousel
Each card returns a reply action so the customer can choose a product, category, service, or path directly inside WhatsApp.
Link Carousel
Each card opens a destination created from the template’s base URL and the individual card’s URL suffix.
Complete the production WhatsApp setup before creating carousel templates.
20
Create a carousel template
Open WhatsApp Integration → Templates.
Select Quick Reply Carousel or Link Carousel.
Enter a unique lowercase template name in Meta’s accepted format and choose the language.
Write the shared message body that introduces the cards.
Select the card body format and choose between 2 and 10 sample cards.
Add a publicly accessible HTTPS sample image, realistic title, and description for every card.
For a Quick Reply Carousel, enter the reply label returned by each card.
For a Link Carousel, configure the shared base URL and enter only each card’s URL suffix.
Review the content and select Create Template.
Card-count rule: build the live flow with the same number of cards used in the approved template.
Configure the shared message and card format before adding the sample cards Meta will review. Click to enlarge.
21
Approval and template statuses
After submission, confirm the template appears in Maxbot with Pending status.
Open Meta Message Templates and locate the same name and language.
Wait for Meta’s review; do not create duplicate copies while the template is pending.
When review finishes, return to Maxbot and select Refresh Template Statuses.
Use the template only after Maxbot reports Approved.
If it is Rejected, inspect Meta’s reason, correct the content or samples, and submit a revised template.
22
Use a carousel in a Maxbot flow
Create a topic for the carousel journey and open its Flow Editor.
Add a welcome prompt and quick replies that select the desired carousel path.
Give every quick reply a defined child-block action.
In the child block, enable the card/carousel response and select the approved template.
Add the same number of production cards used in the approved template.
Provide each production image, title, description, and required action value.
For Quick Reply cards, make the returned label match the branch logic.
For Link cards, provide only the suffix when the template already defines the base URL.
Save, link the flow to the WhatsApp project, and test every card action on a real WhatsApp account.
Enable card view in the branch that will send the approved carousel template. Click to enlarge.
23
Dashboard and message logs
Use Dashboard and Message Logs to reconstruct the message path:
Whether Meta delivered the incoming webhook.
Which sender and phone-number asset produced the event.
Whether Maxbot resolved the linked project and active conversation.
Which flow and block handled the input.
Whether the outgoing request reached sent, delivered, read, or failed status.
Any sanitized error code and timestamp needed for troubleshooting.
Support data: share timestamps, status labels, and sanitized errors,never access tokens, App Secrets, verify tokens, or private message content.
24
Security
Use HTTPS for WordPress and the webhook endpoint.
Keep the App Secret and access token private.
Validate Meta’s App Secret signature on incoming webhook requests.
Use a strong, unique verify token.
Use a system-user token with only the required assets and permissions.
Restrict WordPress administrator and Meta Business access.
Rotate credentials after staff, ownership, permission, or exposure changes.
Keep WordPress, Maxbot Core, the add-on, and server dependencies updated.
25
Troubleshooting
Problem
What to check
Add-on activation fails
Maxbot Core must be installed and active. Upload the installable add-on ZIP and verify server compatibility and dependencies.
Webhook verification fails
The callback must be public HTTPS; save Maxbot first; both verify-token values must match exactly; security or cache layers must not block Meta’s verification request.
Use international digits, the correct Phone Number ID and token, an approved template, and a recipient active on WhatsApp.
Token or authorization error
Replace expired development credentials, confirm the system user’s permissions and assigned assets, and regenerate the production token when necessary.
Wrong flow starts
Confirm the Linked WhatsApp Project, project type, assigned flow, trigger keywords, match type, and whether an active conversation already exists.
Template stays Pending or is Rejected
Inspect Meta’s status and reason, verify sample media accessibility and valid content, refresh statuses, then correct and resubmit when needed.
Carousel sends incorrectly
Use an Approved template, match the approved card count and structure, supply all production card fields, and use only the suffix for a Link Carousel with a base URL.
26
Production launch checklist
Maxbot Core and the WhatsApp add-on are active, authorized, and current.
The core flow passes all expected, fallback, validation, join, and ending tests.
The production phone number is registered and its display name is approved.
The App ID, App Secret, WABA ID, Phone Number ID, public number, and system-user token belong to matching production assets.
The callback uses HTTPS, App Secret signature validation is enabled, and the verify token remains private.
The messages subscription and WABA app subscription are active.
The WhatsApp project is enabled, linked, and assigned to the intended flow.
Every live template reports Approved and its payload matches the approved structure.
Two-way tests from at least two recipient accounts succeed and appear in logs.
Token storage, staff access, privacy, logging, and escalation procedures are documented.
27
Retire or uninstall the integration
Back up relevant project, template, and message-log information according to the business’s retention policy.
Disable the linked WhatsApp project so it stops starting new conversations.
Remove or disable Meta webhook subscriptions when the integration is permanently retired.
Revoke the system-user token and remove unnecessary app/business asset assignments.
Review the add-on cleanup setting, then deactivate and remove the add-on.
Keep Maxbot Core installed when other web or channel projects still use it.